A C++/Asm template for PIC/EXE/DLL malware
☆24Aug 12, 2025Updated last year
Alternatives and similar repositories for Imperium
Users that are interested in Imperium are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- PPLwindow PPL Bypass via GetProcessHandleFromHwnd☆54Dec 29, 2025Updated 7 months ago
- Implementing an early exception handler for hooking and threadless process injection without relying on VEH or SEH☆141Aug 31, 2025Updated 11 months ago
- Thats it! An Open-Source Windows UEFI Rootkit☆41Jul 19, 2025Updated last year
- Porting of NPPSPY by Grzegorz Tworek to 'man in the middle' the user logon process, and store the user's name and password in an unassumi…☆20Apr 24, 2023Updated 3 years ago
- Mirage is a PoC memory evasion technique that relies on a vulnerable VBS enclave to hide shellcode within VTL1.☆108Feb 25, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- SACL Scanner is a tool designed to scan and analyze SACLs.☆52Feb 13, 2025Updated last year
- Minimalistic HTTP(S) client for the NT kernel☆61Dec 1, 2025Updated 8 months ago
- A bunch of shenanigans using functions, VEH and more☆37Jun 8, 2025Updated last year
- Azure Blob Storage C2 Profile for Mythic☆30Jan 30, 2026Updated 6 months ago
- Alternative Read and Write primitives using Rtl* functions the unintended way.☆79Aug 25, 2025Updated 11 months ago
- Run native PE or .NET executables entirely in-memory. Build the loader as an .exe or .dll—DllMain is Cobalt Strike UDRL-compatible☆275Jun 18, 2025Updated last year
- ☆25Sep 6, 2025Updated 11 months ago
- PIC shellcode (C/C++) development toolkit designed for malware developers.☆132Dec 23, 2025Updated 7 months ago
- .NET port of Leron Gray's azbelt tool.☆26Sep 21, 2023Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Usermode NT Explorer - Query kernel addresses, translate virtual to physical addresses, inspect the PFN database, and more.☆90Mar 16, 2026Updated 4 months ago
- Command Augmentation support for BOFs and .NET assemblies across agents☆50Jul 30, 2026Updated 2 weeks ago
- Windows C/C++ development environment on Linux☆18Mar 29, 2026Updated 4 months ago
- Shellcode Loader Utilizing ETW Events☆66Feb 26, 2025Updated last year
- Finding Truth in the Shadows☆128Jan 26, 2023Updated 3 years ago
- ☆41Nov 25, 2025Updated 8 months ago
- Reports on Driver, LSASS and other security services mitigations☆35Aug 18, 2025Updated 11 months ago
- A QoL tool to obfuscate shellcode.☆26Jun 2, 2026Updated 2 months ago
- ☆19Feb 13, 2026Updated 6 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Collection of Win32 with C++/Assembly for Hooking, Patch and Reversing PE file☆18Nov 7, 2022Updated 3 years ago
- vm_str.hpp is a header only string obfuscator.☆116Aug 24, 2025Updated 11 months ago
- Comprehensive Windows Syscall Extraction & Analysis Framework☆173Aug 30, 2025Updated 11 months ago
- A powerful Windows UI monitoring and DNS exfiltration tool written in Rust, combining advanced UI event capture capabilities with secure …☆20Mar 6, 2025Updated last year
- Local SYSTEM auth trigger for relaying - X☆160Jul 23, 2025Updated last year
- Extra cmdlets to help with quering security related information from Azure☆15Jul 28, 2026Updated 2 weeks ago
- XPN's RpcEnum but based on IDA instead of Ghidra☆21Aug 17, 2019Updated 6 years ago
- LibWinHttp is a simplified WinHTTP wrapper designed as a Crystal Palace shared library for implant development. Its primary purpose is to…☆47Nov 4, 2025Updated 9 months ago
- 🛡️ Advanced PE obfuscation & protection detector. Scans binaries for Obfus.h signatures, anti-debug mechanisms, virtualization dispatche…☆27May 20, 2026Updated 2 months ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- A cross-platform C++ framework for building Windows shellcode☆177Apr 21, 2026Updated 3 months ago
- Attempting to Hook LSASS APIs to Retrieve Plaintext Credentials☆61May 12, 2025Updated last year
- A hacky way of getting cross-arch/platform support in Cobalt Strike☆39Aug 31, 2025Updated 11 months ago
- modified mssqlclient from impacket to extract policies from the SCCM database☆48Feb 24, 2026Updated 5 months ago
- Umbrella will protect your shellcode from the rain.☆31Jun 4, 2025Updated last year
- 64-bit, position-independent implant template for Windows in Rust.☆188Nov 28, 2025Updated 8 months ago
- An OpenGraph extension for secrets☆21Updated this week